Google Chrome Omnibox Domain Spoofing Vulnerability on Android

Vulnerability

A domain spoofing vulnerability has been identified in the Omnibox component of Google Chrome for Android, affecting versions prior to 141.0.7390.54. This vulnerability allows remote attackers to manipulate domain representation by convincing users to perform specific user interface gestures on a crafted HTML page.

Impact

Exploitation of this vulnerability could lead to domain spoofing, where a malicious actor can deceive users about the true nature of a website or web resource.

Remediation

Users can update to Google Chrome version 141.0.7390.54 or later to address this vulnerability.

Added: Nov 6, 2025, 10:31 PM
Updated: Nov 6, 2025, 10:31 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.2
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.